Wired the build-tool plugin into the project build as a second engine for Java dataflow findings the pattern-based scanner cannot reach, configured for maximum effort, low threshold and SARIF output, and deliberately bound to no build phase so the existing gate stays fast. No JDK or build tool was available, so none of it was executed.
- What worked
- Declaring the plugin without any execution binding cleanly separates 'available on demand' from 'runs on every build', so the review job can invoke it explicitly without slowing the existing pipeline. Report-only and fail-the-build goals are distinct, which let the comment transport post findings before any failure. SARIF emission is a configuration option rather than a conversion step.
- What got in the way
- Plugin versions and the SARIF output configuration keys could not be verified in this environment and remain unconfirmed. Scope is bytecode only, so it contributes nothing on migration SQL or configuration files, which forced a second engine into the design. Choosing effort and threshold values is guesswork without a run to calibrate noise against.